Author: jmm-guest Date: 2010-09-15 19:34:39 +0000 (Wed, 15 Sep 2010) New Revision: 15331 Modified: data/CVE/list Log: more work for xulrunner src pkg name change Modified: data/CVE/list ==================================================================--- data/CVE/list 2010-09-15 14:35:57 UTC (rev 15330) +++ data/CVE/list 2010-09-15 19:34:39 UTC (rev 15331) @@ -5735,28 +5735,38 @@ CVE-2010-1214 (Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x ...) {DSA-2075-1} - xulrunner 1.9.1.11-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.6-1 [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-1213 (The importScripts Web Worker method in Mozilla Firefox 3.5.x before ...) - xulrunner 1.9.1.11-1 [lenny] - xulrunner <not-affected> (Only affects 1.9.1 and above) + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.6-1 [lenny] - iceape <not-affected> (Only a stub package) - icedove 3.0.6-1 CVE-2010-1212 (js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6.x ...) - xulrunner <not-affected> (Only affects Firefox 3.6.x and above) + - iceweasel <not-affected> (Only affects Firefox 3.6.x and above) - icedove 3.0.6-1 CVE-2010-1211 (Multiple unspecified vulnerabilities in the browser engine in Mozilla ...) {DSA-2075-1} - xulrunner 1.9.1.11-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.6-1 - icedove 3.0.6-1 [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-1210 (intl/uconv/util/nsUnicodeDecodeHelper.cpp in Mozilla Firefox before ...) - xulrunner <not-affected> (Only affects 1.9.2 and above) + - iceweasel <not-affected> (Only affects 1.9.2 and above) CVE-2010-1209 (Use-after-free vulnerability in the NodeIterator implementation in ...) - xulrunner 1.9.1.11-1 [lenny] - xulrunner <not-affected> (Only affects 1.9.1 and above) + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.6-1 [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-1208 (Use-after-free vulnerability in the attribute-cloning functionality in ...) @@ -5766,6 +5776,7 @@ [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-1207 (Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not ...) - xulrunner <not-affected> (Only affects 1.9.2 and above) + - iceweasel <not-affected> (Only affects 1.9.2 and above) CVE-2010-1206 (The startDocumentLoad function in browser/base/content/browser.js in ...) - iceweasel 3.5.11-1 [lenny] - iceweasel <not-affected> (Vulnerable code not present) @@ -5781,40 +5792,55 @@ [lenny] - bugzilla <no-dsa> (Minor issue) CVE-2010-1203 (The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow ...) - xulrunner <not-affected> (Only affects Firefox 3.6, i.e xulrunner 1.9.2) + - iceweasel <not-affected> (Only affects Firefox 3.6, i.e xulrunner 1.9.2) CVE-2010-1202 (Multiple unspecified vulnerabilities in the JavaScript engine in ...) {DSA-2064-1} - xulrunner 1.9.1.10-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.5-1 [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-1201 (Unspecified vulnerability in the browser engine in Mozilla Firefox ...) {DSA-2064-1} - xulrunner 1.9.1.10-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.5-1 [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-1200 (Multiple unspecified vulnerabilities in the browser engine in Mozilla ...) {DSA-2064-1} - xulrunner 1.9.1.10-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.5-1 [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-1199 (Integer overflow in the XSLT node sorting implementation in Mozilla ...) {DSA-2064-1} - xulrunner 1.9.1.10-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.5-1 - icedove <unfixed> [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-1198 (Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.10 ...) {DSA-2064-1} - xulrunner 1.9.1.10-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.5-1 [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-1197 (Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and ...) {DSA-2064-1} - xulrunner 1.9.1.10-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.5-1 [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-1196 (Integer overflow in the nsGenericDOMDataNode::SetTextInternal function ...) {DSA-2064-1} - xulrunner 1.9.1.10-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.5-1 - icedove <unfixed> [lenny] - iceape <not-affected> (Only a stub package) @@ -7437,6 +7463,8 @@ CVE-2010-0654 (Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, ...) {DSA-2075-1} - xulrunner 1.9.1.11-1 (bug #570743) + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - icedove 3.0.6-1 - iceape 2.0.6-1 [lenny] - iceape <not-affected> (Only a stub package) @@ -8189,6 +8217,8 @@ - xulrunner 1.9.1-1 (low) [etch] - xulrunner <not-affected> (dns prefetching implemented in xulrunner 1.9.1) [lenny] - xulrunner <not-affected> (dns prefetching implemented in xulrunner 1.9.1) + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0-1 (low) [etch] - iceape <not-affected> (dns prefetching implemented in xulrunner 1.9.1) [lenny] - iceape <not-affected> (dns prefetching implemented in xulrunner 1.9.1) @@ -8197,6 +8227,8 @@ - icedove 3.0.2-1 (unimportant) [etch] - icedove <not-affected> (dns prefetching implemented in xulrunner 1.9.1) [lenny] - icedove <not-affected> (dns prefetching implemented in xulrunner 1.9.1) + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape <unfixed> (unimportant) [etch] - iceape <not-affected> (dns prefetching implemented in xulrunner 1.9.1) [lenny] - iceape <not-affected> (dns prefetching implemented in xulrunner 1.9.1) @@ -8860,6 +8892,8 @@ CVE-2010-0183 (Use-after-free vulnerability in the nsCycleCollector::MarkRoots ...) {DSA-2064-1} - xulrunner 1.9.1.10-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.5-1 [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-0182 (The XMLDocument::load function in Mozilla Firefox before 3.5.9 and ...) @@ -8867,10 +8901,14 @@ - xulrunner 1.9.1.9-1 (low) [lenny] - xulrunner <no-dsa> (Minor issue, no upstream fix for 3.0 series) - iceape 2.0.4-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - icedove 3.0.4-1 [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-0181 (Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, and SeaMonkey ...) - xulrunner 1.9.1.9-1 (unimportant) + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.4-1 [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-0180 (Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when ...) @@ -8878,38 +8916,52 @@ CVE-2010-0179 (Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey ...) {DSA-2027-1} - xulrunner 1.9.1.9-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.4-1 [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-0178 (Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before ...) {DSA-2027-1} - xulrunner 1.9.1.9-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.4-1 [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-0177 (Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before ...) {DSA-2027-1} - xulrunner 1.9.1.9-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.4-1 [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-0176 (Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before ...) {DSA-2027-1} - xulrunner 1.9.1.9-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.4-1 - icedove 3.0.4-1 [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-0175 (Use-after-free vulnerability in the nsTreeSelection implementation in ...) {DSA-2027-1} - xulrunner 1.9.1.9-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.4-1 - icedove 3.0.4-1 [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-0174 (Multiple unspecified vulnerabilities in the browser engine in Mozilla ...) {DSA-2027-1} - xulrunner 1.9.1.9-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.4-1 - icedove 3.0.4-1 [lenny] - iceape <not-affected> (Only a stub package) CVE-2010-0173 (Multiple unspecified vulnerabilities in the browser engine in Mozilla ...) - xulrunner 1.9.1.9-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.4-1 - icedove 3.0.4-1 [lenny] - iceape <not-affected> (Only a stub package) @@ -8917,61 +8969,72 @@ CVE-2010-0172 (toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the ...) - xulrunner <not-affected> (vulnerable code introduced in firefox 3.6) - iceape <not-affected> (vulnerable code introduced in firefox 3.6) - NOTE: recheck when versions based on firefox 3.6 get uploaded + - iceweasel <not-affected> (vulnerable code introduced in firefox 3.6) CVE-2010-0171 (Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x ...) {DSA-1999-1} - xulrunner 1.9.1.8-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.3-1 [lenny] - iceape <not-affected> (Lenny package only provide xpcom stubs) - icedove 3.0.2-1 CVE-2010-0170 (Mozilla Firefox 3.6 before 3.6.2 does not offer plugins the expected ...) - xulrunner <not-affected> (vulnerable code introduced in firefox 3.6) - iceape <not-affected> (vulnerable code introduced in firefox 3.6) - NOTE: recheck when versions based on firefox 3.6 get uploaded + - iceweasel <not-affected> (vulnerable code introduced in firefox 3.6) CVE-2010-0169 (The CSSLoaderImpl::DoSheetComplete function in ...) {DSA-1999-1} - xulrunner 1.9.1.8-1 - iceape 2.0.3-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) [lenny] - iceape <not-affected> (Lenny package only provide xpcom stubs) - icedove 3.0.2-1 CVE-2010-0168 (The nsDocument::MaybePreLoadImage function in ...) - xulrunner <not-affected> (vulnerable code introduced in firefox 3.6) - iceape <not-affected> (vulnerable code introduced in firefox 3.6) - NOTE: recheck when versions based on firefox 3.6 get uploaded + - iceweasel <not-affected> (vulnerable code introduced in firefox 3.6) CVE-2010-0167 (The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x ...) {DSA-1999-1} - xulrunner 1.9.1.8-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.3-1 [lenny] - iceape <not-affected> (Lenny package only provide xpcom stubs) - icedove 3.0.2-1 CVE-2010-0166 (The gfxTextRun::SanitizeGlyphRuns function in ...) - xulrunner <not-affected> (vulnerable code introduced in firefox 3.6) - iceape <not-affected> (vulnerable code introduced in firefox 3.6) - NOTE: recheck when versions based on firefox 3.6 get uploaded + - iceweasel <not-affected> (vulnerable code introduced in firefox 3.6) CVE-2010-0165 (The TraceRecorder::traverseScopeChain function in js/src/jstracer.cpp ...) - xulrunner <not-affected> (vulnerable code introduced in firefox 3.6) - iceape <not-affected> (vulnerable code introduced in firefox 3.6) - NOTE: recheck when versions based on firefox 3.6 get uploaded + - iceweasel <not-affected> (vulnerable code introduced in firefox 3.6) CVE-2010-0164 (Use-after-free vulnerability in the ...) - xulrunner <not-affected> (vulnerable code introduced in firefox 3.6) - iceape <not-affected> (vulnerable code introduced in firefox 3.6) - NOTE: recheck when versions based on firefox 3.6 get uploaded + - iceweasel <not-affected> (vulnerable code introduced in firefox 3.6) CVE-2010-0163 (Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 ...) {DSA-2025-1} - icedove 3.0.4-1 (medium) CVE-2010-0162 (Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and ...) {DSA-1999-1} - xulrunner 1.9.1.8-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) [etch] - xulrunner <end-of-life> - iceape 2.0.3-1 [lenny] - iceape <not-affected> (Lenny package only provide xpcom stubs) CVE-2010-0161 (The nsAuthSSPI::Unwrap function in extensions/auth/nsAuthSSPI.cpp in ...) - xulrunner <not-affected> (Windows-specific) - iceape <not-affected> (Windows-specific) + - iceweasel <not-affected> (Windows-specific) CVE-2010-0160 (The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 ...) - xulrunner 1.9.1.8-1 [etch] - xulrunner <not-affected> (web workers introduced in gecko 1.9.1) [lenny] - xulrunner <not-affected> (web workers introduced in gecko 1.9.1) + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.3-1 [etch] - iceape <not-affected> (web workers introduced in gecko 1.9.1) [lenny] - iceape <not-affected> (web workers introduced in gecko 1.9.1) @@ -8979,6 +9042,8 @@ {DSA-1999-1} - xulrunner 1.9.1.8-1 [etch] - xulrunner <end-of-life> + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.3-1 [lenny] - iceape <not-affected> (Lenny package only provide xpcom stubs) - icedove 3.0.2-1 @@ -10907,24 +10972,34 @@ {DSA-1999-1} - xulrunner 1.9.1.8-1 [etch] - xulrunner <end-of-life> + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0.3-1 [lenny] - iceape <not-affected> (Lenny package only provide xpcom stubs) CVE-2009-3987 (The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and ...) - xulrunner <not-affected> (Windows-specific vulnerability) CVE-2009-3986 (Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey ...) {DSA-1956-1} + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - xulrunner 1.9.1.6-1 [etch] - xulrunner <end-of-life> (Etch Packages no longer covered by security support) CVE-2009-3985 (Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey ...) {DSA-1956-1} + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - xulrunner 1.9.1.6-1 [etch] - xulrunner <end-of-life> (Etch Packages no longer covered by security support) CVE-2009-3984 (Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey ...) {DSA-1956-1} + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - xulrunner 1.9.1.6-1 [etch] - xulrunner <end-of-life> (Etch Packages no longer covered by security support) CVE-2009-3983 (Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey ...) {DSA-1956-1} + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - xulrunner 1.9.1.6-1 [etch] - xulrunner <end-of-life> (Etch Packages no longer covered by security support) CVE-2009-3982 (Multiple unspecified vulnerabilities in the JavaScript engine in ...) @@ -10933,14 +11008,20 @@ [etch] - xulrunner <not-affected> (Only affects Firefox 3.5) CVE-2009-3981 (Unspecified vulnerability in the browser engine in Mozilla Firefox ...) {DSA-1956-1} + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - xulrunner 1.9.1 NOTE: Only affects Firefox 3 CVE-2009-3980 (Multiple unspecified vulnerabilities in the browser engine in Mozilla ...) - xulrunner 1.9.1.6-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) [etch] - xulrunner <end-of-life> (Mozilla packages from oldstable no longer covered by security support) [lenny] - xulrunner <not-affected> (Only affects Firefox 3.5) CVE-2009-3979 (Multiple unspecified vulnerabilities in the browser engine in Mozilla ...) {DSA-1956-1} + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - xulrunner 1.9.1.6-1 [etch] - xulrunner <end-of-life> (Mozilla packages from oldstable no longer covered by security support) CVE-2009-3978 (The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp ...) @@ -12680,11 +12761,15 @@ {DSA-2045-1} - libtheora 1.1 (bug #572950) [etch] - libtheora <not-affected> (vulnerable code not present) + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - xulrunner 1.9.1.6-1 [etch] - xulrunner <end-of-life> (Mozilla packages from oldstable no longer covered by security support) [lenny] - xulrunner <not-affected> (Video playback capabilities were added in 3.5) CVE-2009-3388 (liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before ...) - liboggplay 0.2.1~git20091227-1.1 (bug #575743) + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - xulrunner 1.9.1.6-1 [etch] - xulrunner <end-of-life> (Mozilla packages from oldstable no longer covered by security support) [lenny] - xulrunner <not-affected> (Video playback capabilities were added in 3.5) @@ -12697,6 +12782,8 @@ CVE-2009-3385 (The mail component in Mozilla SeaMonkey before 1.1.19 does not ...) {DSA-1922-1} - xulrunner 1.9.0.15-1 + - iceweasel 3.5.11-2 + [lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner) - iceape 2.0-1 [lenny] - iceape <not-affected> (stub package) CVE-2009-3384 (Multiple unspecified vulnerabilities in WebKit in Apple Safari before ...) @@ -33483,7 +33570,6 @@ NOT-FOR-US: Alias Manager in Apple Mac OS X CVE-2008-2307 (Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as ...) - webkit 1.0.1-1 - - kde4libs <unfixed> - qt4-x11 4:4.6.2-4 [lenny] - qt4-x11 <no-dsa> (Minor impact, no apps in Lenny which use qtwebkit ) NOTE: QT4 might be fixed earlier, but only 4.6.2 was checked against